Sub-processor Register

Last Updated: August 27, 2026

1. What this is

A sub-processor is a third party that may process your data on our behalf. This page lists every one of them, and — the part that matters most to a procurement or risk team — which of them are reachable at all in each deployment shape.

Where a row says Not yet confirmed, we have not yet confirmed the underlying agreement. Those are facts about contracts, not about our software, so no test of ours can check them. We leave them visibly open rather than filling them with a plausible answer.

2. Where your data actually lives

Two hosts, and the difference matters. The application at app.lexcore.ng — including the database and every document you upload — runs on MTN Cloud in Lagos, Nigeria. The public marketing site at lexcore.ng is hosted separately on Hostinger.

Hostinger sees who visited a marketing page. It never receives a matter, a document, or a user account. When you ask where your data is, the answer is MTN Cloud, Lagos.

3. Reachability by deployment shape

"Reachable" means our software can connect to it in that configuration — not that it is used on every request.

Sub-processor classManagedManaged (sovereign)Dedicated / on-premiseAir-gapped
AI model providers (§4)YesNoCustomer's own accountNo
Local AI (runs inside the deployment)YesYesYesYes
LexCore-operated infrastructure (§5)YesYesCustomer-operatedNo
Payment processors (§6)YesYesNo — licensed offlineNo
Transactional email (§7)YesYesCustomer's own mail serverNo
Optional connectors (§8)Opt-inOpt-inOpt-inNo
Analytics and error tracking (§10)Opt-inSelf-hostedSelf-hostedNo

In sovereign mode a cloud AI provider is never constructed at all. There is no credential to leak and no setting to get wrong. That is a structural guarantee, not a configuration choice.

4. AI model providers

Each of these receives prompt text and document excerpts, which for LexCore means contract content. They are reachable on the managed quality tier and in customer-owned cloud accounts. None is reachable in sovereign, dedicated or air-gapped mode.

ProviderUsed for
Anthropic (Claude)Default reasoning on the quality tier
AWS Bedrock (Claude)Alternative route for AWS-committed organisations
Google Vertex AI (Gemini)Optional, quality tier
Google AI Studio (Gemini)Optional, quality tier
OpenAIOptional, selected by the organisation
Azure OpenAIMicrosoft 365 estates; the customer's own Azure tenant
CerebrasCloud GPU inference
FireworksCloud GPU inference
TogetherCloud GPU inference
Z.ai / GLMOptional
MistralDocument OCR — cloud-tolerant customers only

Ollama, vLLM and DiffusionGemma run inside the deployment. No data leaves, so they are not sub-processors.

5. Infrastructure we operate

Applies to the managed deployment. On a dedicated deployment you operate all of this.

Sub-processorPurposeRegionAgreement
MTN Cloud (Nigeria)Compute and storage for the applicationNigeria (Lagos)Not yet confirmed
HostingerPublic marketing site and DNS only — no customer dataNot yet confirmedNot yet confirmed
AWS S3 and KMSObject storage and key management, where configuredNot yet confirmedNot yet confirmed
Auth0 (Okta)Sign-inNot yet confirmedNot yet confirmed
SentryError reporting, if enabledNot yet confirmedNot yet confirmed

PostgreSQL and Redis run on MTN Cloud infrastructure we operate. They are not separate third parties.

6. Payments

No card details ever reach LexCore. We receive billing metadata only, and every provider webhook is signature-verified.

Sub-processorCurrencies
FlutterwaveNGN, other African currencies, USD
PaystackNGN
StripeUSD

Dedicated deployments are licensed offline, so no payment processor is reachable from a dedicated or air-gapped installation at all.

7. Transactional email

Invitations, sign-in links, alerts and reminders. One provider is active at a time, and the current provider is Postmark. Adapters for Resend and SendGrid exist in the software but are not in use.

Email subject lines and invitations can carry matter and party names, so this is a genuine processor rather than plumbing.

8. Optional connectors

None of these is reachable until you connect it. Each is authorised per organisation, and you can disconnect any of them.

Sub-processorWhat it receives
SlackNotifications and requests
Microsoft Teams, OneDrive, SharePointNotifications; documents you choose to import
Google Workspace and DriveNotifications; documents you choose to import
Google and Microsoft CalendarEvent details for deadline sync
DocuSignDocuments sent for signature, and signer identities
Google Sign-In (through Auth0)Your email address, name and Google account id — for sign-in only

Our search index (Typesense) and web search (SearxNG) are self-hosted inside the deployment. They are not third parties.

9. Google API Services — Limited Use

LexCore's use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.

In practice: we do not use Google Workspace data to train any AI model, we do not sell it, we do not transfer it to others except as needed to provide the feature you connected or where the law requires it, and no person reads it except with your explicit permission or for security and legal reasons.

10. Analytics and error tracking

Neither carries document text. Both can carry information identifying which organisation did something, so we treat them as processors rather than as plumbing.

On the Nigerian deployment the analytics tool is self-hosted Umami inside the same private network, so no third party is engaged at all. PostHog Cloud and hosted Sentry are reachable only where an organisation explicitly points us at them.

11. Changes to this register

We update this page when a sub-processor is added or removed, and we notify customers where the contract requires it. Adding a new AI provider without listing it here fails our build — completeness of the provider list is enforced by an automated test, not by a reviewer remembering.

Questions about this register: dpo@lexcore.ng